Skip to content

Unexpected behavior on http status codes. Documentation missing. #602

@Lokowandtg

Description

@Lokowandtg

When a request is not authenticated or not authorized, the expected http behavior is to return status codes 401 or 403. The implementation instead returns a status code 404 (not found) to discourage malicious actors.
The documentation for this behavior is missing.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status

    Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions